Executive Summary
A Fortune 500 financial services company watched account takeovers climb on its digital banking apps. They plugged Revealer.US credential monitoring into the login path. Six months later, successful ATOs were down 85%.
The Challenge
Background
The company operates multiple digital banking platforms serving over 10 million customers. In early 2024, they observed:
- 340% increase in credential stuffing attacks
- $2.3M in fraud losses attributed to ATO
- 45,000 customer accounts compromised in Q1 alone
- Increasing customer complaints and churn
Root Causes
The investigation pointed at four sources, none of them surprising:
- Password reuse: Customers using the same credentials across multiple services
- Stealer malware: Customer devices infected with infostealers harvesting credentials. Exposure of this kind shows up in stealer log data long before the fraud does.
- Phishing: Sophisticated phishing campaigns targeting customers
- Dark web sales: Active trading of their customer credentials on underground forums
Previous Defenses
The company had implemented standard defenses:
- Rate limiting on login endpoints
- Device fingerprinting
- Risk-based authentication
- MFA (optional for customers)
Those controls caught the noisy stuff. They did not catch logins that used real passwords and stolen session cookies, because those look like the customer.
The Solution
Implementation Approach
The security team put Revealer.US in three places, in this order:
Phase 1: Exposure Assessment (Week 1-2)
Initial analysis, run the same way as a data breach lookup, revealed:
- 127,000 customer email addresses present in breach databases
- 34,000 credentials with associated passwords
- 8,500 records in recent device exposures
Phase 2: Proactive Reset Campaign (Week 3-4)
For high-confidence exposures:
- Forced password resets for 15,000 highest-risk accounts
- Personalized security notifications explaining the risk
- Streamlined re-enrollment with MFA incentives
Phase 3: Real-Time Monitoring (Ongoing)
Integrated the Revealer.US API into the authentication flow (see the API documentation for endpoint details):
Login Attempt
│
▼
┌──────────────────┐
│ Standard Auth │
│ (username/pass) │
└────────┬─────────┘
│
▼
┌──────────────────┐
│ Revealer.US Check │◀──── Real-time credential
│ (async lookup) │ exposure check
└────────┬─────────┘
│
┌────┴────┐
│ Exposed?│
└────┬────┘
│
Yes │ No
▼ ▼
Step-Up Normal
Auth Access
When credentials matched known exposures:
- Require additional authentication factor
- Flag session for enhanced monitoring
- Queue for proactive password reset notification
Results
Six-Month Outcomes
| Metric | Before | After | Change |
|---|---|---|---|
| Successful ATO attacks | 15,000/month | 2,250/month | -85% |
| Fraud losses | $380K/month | $52K/month | -86% |
| Customer complaints | 890/month | 145/month | -84% |
| Mean time to detect | 18 days | 4 hours | -99% |
ROI Analysis
Annual savings:
- Fraud reduction: $3.9M
- Customer service costs: $240K
- Investigation hours: $180K
- Total: $4.32M
Investment:
- Revealer.US subscription: $120K/year
- Integration development: $85K (one-time)
- ROI: 35x in first year
Revealer.US pricing runs from a free tier through paid self-serve plans starting at $12.99/mo, with custom Enterprise pricing for deployments at this scale. See pricing for current tiers.
Key Success Factors
1. Reset before the stuffing starts
They pulled exposed credentials out of circulation before the stuffing campaigns hit those accounts.
2. Customer-Friendly Approach
Password reset communications explained the "why" without causing alarm:
"We detected that your email address appeared in a third-party data breach. While our systems were not compromised, we're requiring a password update as a precaution..."
3. Continuous Monitoring
New dumps landed every day, so a credential that was clean on Monday could be in a log by Friday. Revealer.US searches 800+ platforms, public records, and known breach datasets from one query (email, username, phone, name, or address), which is how those fresh hits reached the auth flow the same day.
4. Leave the existing stack in place
Exposure checks sat on top of rate limits, device fingerprinting, and risk-based auth. None of those went away.
Lessons Learned
- Count the exposed accounts first: 127,000 emails in breach data is what justified the forced-reset list; without that number, the campaign would have been a guess.
- Tell customers why: A reset email that names a third-party breach gets fewer angry tickets than a silent lockout.
- Integrate, don't replace: Monitoring fed step-up auth. It did not replace rate limits or device fingerprinting.
- Bring numbers to the steering committee: Monthly ATO counts and fraud dollars are what got the subscription renewed.
Conclusion
The 85% drop in successful ATOs, and the $3.9M in annual fraud that went with it, came from resetting exposed passwords and stepping up auth on matches, not from a new WAF rule. Customer complaint volume fell with the fraud.
Note: Revealer.US is not a consumer reporting agency, and its results may not be used for employment, tenant, or credit decisions.
Ready to reduce your organization's account takeover risk? Contact our team for a personalized assessment.